4 ms·
Could someone (@dang ?) fix the title please? It is /etc/shadow , not /etc./Shadow
by satish-setty 4y ago
Could someone (@dang ?) fix the title please? It is /etc/shadow , not /etc./Shadow
- deleted 4y ago[deleted]
- technion 4y agoThere's a reason for this - having /etc/shadow in the title breaks searching from Algolia search due to a WAF. eg try this https://hn.algolia.com/?query=What%20We%20Do%20in%20the%20%2Fetc%2Fshadow%20%E2%80%93%20Cryptography%20with%20Passwords&type=story&dateRange=all&sort=byDate&storyText=false&prefix&page=0 https://hn.algolia.com/?query=What%20We%20Do%20in%20the%20%2...
- deleted 4y ago[deleted]
- ivanr 4y agoThat’s so depressing.
- rtev 4y agoThat WAF needs to be tuned. If they’re worried about the possibility of a local file read that can disclose /etc/shadow, there are much bigger issues.
- thayne 4y agoOr it is defense in depth. Although blocking it even if the / is percent encoded seems a bit excessive, especially as a default.
- thaumaturgy 4y ago...that's a Cloudflare security page. Is this a default setting for one of Cloudflare's security options, or did Algolia specifically add this to some edge detection worker or something? I'm curious which party is being ridiculous.
- technion 4y agoI just hit a website I know has an entirely default config on the free plan as https://website/q=cat https://website/q=cat /etc/shadow and got the same exact error page.
- some_furry 4y agoSo much for CloudFlare's stance on free speech, I'm being censored for comedy! (The title is a wordplay on What We Do in the Shadows.) Joke aside, I can understand why, generally, protecting from /etc/shadow disclosures is a good default, but it should be possible to disable this particular protection. If anyone knows how, that'd be good to share. EDIT: A bypass has been discovered https://infosec.exchange/@jsmall/109647469548014823 https://infosec.exchange/@jsmall/109647469548014823
- arbol 4y agoIt's a great title
- thaumaturgy 4y agoOhhh Cloudflare. I have to wonder how many sites are left that are actually vulnerable to having their shadow file dumped. Even for the sites that have filesystem traversal vulns, how many of those would cough up something publicly accessible from the shadow file?